Логотип exploitDog
bind:"BDU:2019-04729" OR bind:"CVE-2019-13057"
Консоль
Логотип exploitDog

exploitDog

bind:"BDU:2019-04729" OR bind:"CVE-2019-13057"

Количество 12

Количество 12

fstec логотип

BDU:2019-04729

больше 6 лет назад

Уязвимость демона slapd пакета OpenLDAP, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2019-13057

больше 6 лет назад

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 4.9
EPSS: Низкий
redhat логотип

CVE-2019-13057

больше 6 лет назад

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-13057

больше 6 лет назад

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2019-13057

больше 6 лет назад

An issue was discovered in the server in OpenLDAP before 2.4.48. When ...

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-5x95-66xj-7chm

больше 3 лет назад

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 4.9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:14353-1

почти 6 лет назад

Security update for openldap2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2390-1

больше 6 лет назад

Security update for openldap2

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2176-1

больше 6 лет назад

Security update for openldap2

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2019:2157-1

больше 6 лет назад

Security update for openldap2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:1210-1

почти 6 лет назад

Security update for openldap2

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2019:2395-1

больше 6 лет назад

Security update for openldap2

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
fstec логотип
BDU:2019-04729

Уязвимость демона slapd пакета OpenLDAP, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 6.5
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-13057

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 4.9
1%
Низкий
больше 6 лет назад
redhat логотип
CVE-2019-13057

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 6.5
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-13057

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 4.9
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-13057

An issue was discovered in the server in OpenLDAP before 2.4.48. When ...

CVSS3: 4.9
1%
Низкий
больше 6 лет назад
github логотип
GHSA-5x95-66xj-7chm

An issue was discovered in the server in OpenLDAP before 2.4.48. When the server administrator delegates rootDN (database admin) privileges for certain databases but wants to maintain isolation (e.g., for multi-tenant deployments), slapd does not properly stop a rootDN from requesting authorization as an identity from another database during a SASL bind or with a proxyAuthz (RFC 4370) control. (It is not a common configuration to deploy a system where the server administrator and a DB administrator enjoy different levels of trust.)

CVSS3: 4.9
1%
Низкий
больше 3 лет назад
suse-cvrf логотип
SUSE-SU-2020:14353-1

Security update for openldap2

почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2390-1

Security update for openldap2

больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2176-1

Security update for openldap2

больше 6 лет назад
suse-cvrf логотип
openSUSE-SU-2019:2157-1

Security update for openldap2

больше 6 лет назад
suse-cvrf логотип
SUSE-SU-2020:1210-1

Security update for openldap2

почти 6 лет назад
suse-cvrf логотип
SUSE-SU-2019:2395-1

Security update for openldap2

больше 6 лет назад

Уязвимостей на страницу